TL;DR: AI agents now access sensitive data, invoke workflows, and make multi-step decisions across enterprise systems, creating a non-deterministic risk model that traditional security playbooks were not built to handle, according to Zenity. The governance problem is no longer discovery alone, but controlling behaviour that changes at runtime and spans systems, permissions, and data flows.
Editorial analysis by NHI Mgmt Group, based on content published by Zenity: “Securing the AI That Runs the Enterprise: Zenity + ServiceNow SecOps”.
Key questions
Q: What breaks when AI agent security is handled like ordinary application security?
A: Application security assumes a relatively stable workload boundary and a predictable request path.
Q: Why do AI agents create a different data security problem from standard user workflows?
A: AI agents can operate faster than human review, chain multiple tool calls, and move data across systems without a pause for approval.
Q: What are the signs that AI posture management is failing?
A: Common signs include exposed notebooks, untracked models or datasets, inconsistent access policies, and security teams lacking a unified view of activity across tools and clouds.
Practitioner guidance
- Define a SecOps operating model for AI agents Place agent inventory, risk scoring and remediation inside the workflow security teams already use for triage and incident handling.
- Build a contextual agent inventory Track each agent’s workflows, topics, actions, APIs, integrations, identities, permissions, credentials, data sources and dependencies.
- Continuously assess agent posture Look for excessive permissions, unsafe prompt logic, broken integrations, compliance gaps and drift as agents and their environments change.
Bottom line: AI agents change the security problem from static access management to continuous governance of runtime behaviour.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agent security is now a SecOps and identity governance problem, not a sidecar AI issue. When agents access data, invoke workflows, and trigger external actions, they behave like non-human identities with broader runtime variance than traditional service accounts. That means the security team cannot rely on static application assumptions or one-time onboarding checks. The implication is that agent governance must sit inside the same operational model that handles access, risk, and response.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- 33% of organisations report their AI agents have accessed inappropriate or sensitive data beyond their intended scope, which shows the behaviour problem is already operational, not theoretical.
A question worth separating out:
Q: How should organisations respond when AI agent risk appears in SecOps?
A: Organisations should triage it like any other active security issue, with ownership, context, and remediation in the same queue used for operational incidents. The point is to avoid treating agent risk as a separate AI programme. It belongs in the control path where investigation and response already occur.
👉 Read our full editorial: AI agent security needs SecOps-native governance, not static controls
SecOps-native governance is the right control plane for AI agents because the risk is operational, not just architectural. The article’s central point is that agents do not sit still long enough for static security assumptions to remain valid. Once agents can invoke workflows, call APIs and change behaviour in context, the security model has to move into the operational workflow where investigations and remediation already happen. The practitioner conclusion is that agent governance must be embedded where risk is actually handled, not bolted on as a separate review process.
A few things that frame the scale:
- 69% of security leaders agree identity management must fundamentally shift to address agentic AI systems, according to the 2026 Infrastructure Identity Survey.
- Gartner predicts that more than 50% of successful cyberattacks against AI agents through 2029 will exploit access control weaknesses.
A question worth separating out:
Q: How should teams govern AI agents that run across multiple runtimes?
A: Teams should govern them with a shared trace schema, consistent evaluation criteria, and clear ownership for tool access. Portability changes the execution layer, but it does not remove the need to prove what the agent did, why it did it, and whether the behaviour stayed inside policy across environments.
👉 Read our full editorial: AI agent security needs SecOps-native governance, not static controls